Privacy Act 2026

Australian Privacy Act Penalties 2026: What Non-Compliance Actually Costs (From $66K to $50M)

The three-tier civil penalty regime under Australia's Privacy Act 1988, explained for 2026 — the low tier (up to $330k, $66k infringement notices), the mid tier (up to $3.3M) and the high tier (up to $50M / 3x benefit / 30% turnover). Kept separate, source-checked.

By Daniel Ebiau, AMLCompliant ·

The 2024 privacy amendments gave the regime real financial teeth — but the headline "$50 million" figure is widely misquoted as if it applies to any breach. It does not. Australia's Privacy Act 1988 has three separate penalty tiers, and matching the right figure to the right conduct matters. Here is the honest breakdown.

The three tiers — keep them separate

TierApplies toMaximum
HighSerious interference with privacyThe greater of $50M, 3× the benefit obtained, or 30% of adjusted turnover for the period
MidInterference with privacy that is not "serious"Up to $3.3M
LowAdministrative contraventions (e.g. a non-compliant privacy policy under APP 1)Up to $330,000 for incorporated entities, enforceable by infringement notice

(Sources: Clyde & Co; MinterEllison.)

Do not merge these. A non-compliant privacy policy is a low-tier matter — it does not carry the $50M maximum. The high-tier maximum is reserved for serious interference. Conflating them is the single most common error in privacy commentary.

Infringement notices — the everyday risk

Separate from the tiers above, the OAIC can issue infringement notices up to $66,000 for a non-compliant privacy policy. Note this varies by entity type — some sources cite $19,800 for a body corporate versus $66,000 for a publicly listed entity — so read it as "up to $66,000", not a flat figure for everyone. This is the kind of action that flows from things like the OAIC's early-2026 compliance sweep. (Source: MinterEllison.)

Why the low tier should worry small businesses most

The eye-catching $50M number grabs headlines, but for most small Australian businesses the realistic exposure is the low tier — penalties and infringement notices for basics like a non-compliant privacy policy or a missed automated decision-making disclosure. These are the cheapest things to get right and the easiest to get wrong.

The cheapest insurance is compliance

  • Get your privacy policy compliant — see

how to write one.

so the low-tier basics are covered.

Run the free checker to see which obligations — and which risks — apply to you.

General information only, not legal or compliance advice. Penalty figures are drawn from reputable legal commentary on the 2024 amendments, current to June 2026. Tiers apply to different conduct and must not be combined. Confirm your position at oaic.gov.au or with a qualified adviser. Last verified: 8 June 2026.

Run the free ML/TF risk assessment →

Frequently asked questions

What's the maximum penalty under the Privacy Act?
The high tier — for serious interference with privacy — reaches the greater of $50 million, three times the benefit obtained, or 30% of adjusted turnover during the relevant period. This is distinct from the mid and low tiers. Sources — Clyde & Co; MinterEllison.
Can the OAIC fine me for a non-compliant privacy policy?
Yes — the OAIC can issue infringement notices up to $66,000 for a non-compliant privacy policy (with entity-type variation), and the low penalty tier for administrative breaches reaches up to $330,000 for incorporated entities. This is the low tier, not the high tier. Source — MinterEllison.
Is this legal advice?
No. General information, current to June 2026. Confirm your obligations with the OAIC or a qualified adviser.
privacy act penaltiescivil penaltyoaicinfringement noticeprivacy act 1988